Description
Enabling SSLv2, SSLv3, TLS 1.0, or TLS 1.1 in a Classic ELB SSL negotiation policy allows connections using outdated protocols. Check whether each protocol is enabled, as well as its attribute name.
Potential impact
Known weaknesses in older SSL/TLS protocols or their cipher suites can weaken transport security between clients and the load balancer.
Remediation
Disable outdated protocols and choose a policy that uses TLS 1.2. For a custom policy, also configure the allowed cipher suites and associate the policy with the HTTPS listener.
Examples
The examples show only the protocol attribute of a custom policy. The revised example enables TLS 1.2; configure cipher suites and the listener association separately.
Before
resource "aws_load_balancer_policy" "example" {
load_balancer_name = aws_elb.wu_tang.name
policy_name = "wu-tang-ssl"
policy_type_name = "SSLNegotiationPolicyType"
policy_attribute {
name = "Protocol-TLSv1"
value = "true"
}
}
After
resource "aws_load_balancer_policy" "example" {
load_balancer_name = aws_elb.wu_tang.name
policy_name = "wu-tang-ssl"
policy_type_name = "SSLNegotiationPolicyType"
policy_attribute {
name = "Protocol-TLSv1.2"
value = "true"
}
}